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Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the application: 
Listing of Claims: 

1. (Currently amended) A method for detecting unauthorized intrusion in a network 
system, comprising the steps of: 

receiving packet level activity information from the network; 

sorting port specific activity information from the received packet level activity 
information by IP/user ; 

converting the sorted IP/user port specific activity information to human behavioral 
measures of intent ; 

monitoring the port sp e cific activity information converted human behavioral measures; 

and 

executing at least one of a blocking action or a tracking action based upon the monitored 
port sp e cific human behavioral measures activity information . 

2. (Original) The method according to claim 1, wherein the step of monitoring includes: 
identifying presence of at least one activity from the port specific activity information; 
assigning a binary representation (1 = present, 0=absent) to the at least one identified 

activity; and 

generating an assessment based upon the binary rating. 
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3. (Original) The method according to claim 2, wherein the step of generating an 
assessment includes associating the binary rating with an assessment based upon predetermined 
behavioral criteria. 

4. (Original) The method according to claim 3, wherein the step of generating an 
assessment includes mapping the assessment on at least one two-dimensional grid. 

5. (Original) The method according to claim 4, wherein the step of mapping occurs 
dynamically and in real-time. 

6. (Original) The method according to claim 2, wherein the step of generating an 
assessment includes generating a profile of user based upon the monitored port specific activity 
information. 

7. (Original) The method according to claim 2, wherein the step of generating an 
assessment is carried out utilizing a back propagation network. 

8. (Original) The method according to claim 7 wherein the back propagation network 
includes psychological assessment information. 
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9. (Original) The method according to claim 2, wherein the assessment is one of high 
deception/high expertise, high deception/low expertise, low deception/high expertise and low 
deception/low expertise. 

10. (Original) The method according to claim 1, wherein the blocking action includes 
sending a blocking command to a firewall for blocking further network access. 

11. (Original) The method according to claim 1, wherein the tracking action includes storing 
activity information in a tracking module. 

12. (Currently Amended) A system for preventing unauthorized intrusion in a network 
system, comprising: 

a traffic sorter that receives a copy of the network activity and sorts such activity by 
IP/users ; 

an activity monitor operatively coupled to the traffic sorter for monitoring converted 
human behavior measures by IP/users, that is based upon a copy of the network activity ; 

an inter-port fusion module operatively coupled to the activity monitor that fuses 
assessments from one or more assessment engines that monitor behavior measures by port and 
non-port specific behavior conversions ; and 

an outcome director operatively coupled to the inter-port fusion monitor that determines 
whether to block or track EP/users on a user basis based upon assessed behavioral measures of 
intent. 
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13. (Original) The system according to claim 12, wherein the activity monitor includes at 
least one dedicated port monitor. 

14. (Original) The system according to claim 13, wherein, the at least one dedicated port 
monitor includes a packet level analysis module, an activity translator module and an assessment 
module. 

15. (Original) The system according to claim 14, wherein the assessment module includes a 
back propagation network. 

16. (Original) The system according to claim 15, wherein the back propagation network 
includes psychological assessment information. 

17. (Original) The system according to claim 14, wherein the traffic sorter receives packet 
level activity information from the network and sorts the port specific activity information from 
the network. 

18. (Original) The system according to claim 14, wherein the activity monitor monitors the 
port specific activity information. 
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19. (Original) The system according to claim 14, wherein the activity translator module 
assigns a binary rating based upon presence (1) or absence (0) of at least one activity detected by 
the packet level analysis module. 

20. (Original) The system according to claim 19, wherein the assessment module generates 
an assessment result based upon the binary rating. 

21. (Original) The system according to claim 19, wherein the assessment module maps the 
assessment result utilizing at least one of a two dimensional grid or X dimensional grid for 
optional real-time viewing of a user's intent. 

22. (Original) The system according to claim 20, wherein an outcome director initiates at 
least one of a blocking command or a tracking command based upon the assessment result. 

23. (Original) The system according to claim 22, wherein the blocking command is directed 
to a system firewall. 

24. (Original) The system according to claim 23 in which a blocking command results in the 
storage of all session data indicating all user activity and intent until such time as access is 
terminated. 
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25. (Original) The system according to claim 22, wherein the tracking command is directed 
to a tracking module. 

26. (Original) The system according to claim 24, wherein the tracking module includes a 
tracking database for storing activity information that may be used to provide evidence of an 
intruders harmful intent activities and at least one intent assessment during a session. 

27. (Original) The system according to claim 26, wherein the tracking database includes 
neural network assessment and associated information for the intruder that is at least one of 
tracked or blocked. 

28. (Original) The system according to claim 27, wherein the tracking database includes a 
comparison module for comparing the neural network assessment and associated information 
against a second assessment based upon a second network intrusion. 

29. (Original) The system according to claim 28, wherein at least one of a blocking or 
tracking action is executed based upon an output from the comparison module. 

30. (Currently Amended) A system for detecting unauthorized intrusion in a network system, 
comprising: 

sorting means for sorting port specific activity and across port specific activity from 
incoming packet level activity by IP/users ; 
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conversion means for converting the port specific activity and across port specific activity 
to behavioral measures of intent ; 

monitoring means operatively coupled to the sorting means for monitoring the behavioral 
measures sort e d port sp e cific activity ; and 

assessing means operatively coupled to the monitoring means for generating separate and 
independent IP/user assessments ass e ssm e nt based upon the behavior measures . 

31. (Currently Amended) A computer program product, comprising: 

a computer usable medium having computer readable code embodied therein for 
preventing unauthorized intrusion into a computer network, the computer program product 
comprising: 

computer readable program code configured to cause the computer to process a 
copy of network activity in real-time to sort port specific and non-port specific activity 
information by IP/user from packet level activity information received by the computer network; 

computer readable program code configured to cause the computer to covert the 
port and non-port specific activity information to behavioral measures of intent separately and 
independently for each IP/user ; 

computer readable program code configured to cause the computer to monitor the 
behavior measures by IP/user port sp e cific activity information ; and 

computer readable program code configured to cause the computer to execute at 

least one of a blocking action or a tracking action bas e d upon the monitor e d port specific activity 

information for the IP/user if assessed behavioral measures indicate a threat intent . 
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32. (New) The method according to claim 1, wherein the step of receiving the port specific 
activity information includes creating a copy of the network activity sorted by users. 

33. (New) The method according to claim 1, further including the step of sorting non-port 
specific activity information from the received packet level activity information by IP/user; and 
converting the non-port specific activity information to human behavioral measures of intent. 
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